Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-22950

Опубликовано: 01 апр. 2022
Источник: debian
EPSS Низкий

Описание

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libspring-javaunfixedpackage

Примечания

  • https://tanzu.vmware.com/security/cve-2022-22950

  • Only supported for building applications shipped in Debian, see README.Debian.security

EPSS

Процентиль: 89%
0.04547
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 3 лет назад

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

CVSS3: 7.5
redhat
около 3 лет назад

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

CVSS3: 6.5
nvd
около 3 лет назад

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

CVSS3: 6.5
github
около 3 лет назад

Allocation of Resources Without Limits or Throttling in Spring Framework

EPSS

Процентиль: 89%
0.04547
Низкий